patool 4.0.6 之前的版本在 Windows 平台上存在一个操作系统命令注入漏洞,原因是 shell_quote_nt 函数未能对 cmd.exe 的特殊字符或归档文件名中嵌入的双引号进行正确转义。攻击者可以提供精心构造的文件名(例如 report&calc.gz),在通过 shell=True 运行单文件格式时使用 patool 执行任意命令,从而以 patool 进程特权执行恶意操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet